There is a local privilege escalation vulnerability of ZTEs ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zxcloud_irai_firmware | Zte | * | 7.23.32 (excluding) |